Skip to content

Codex-Co-Engineer 3.4.3

Latest

Choose a tag to compare

@ajhcs ajhcs released this 11 Sep 20:12
2907aa4

Codex-Co-Engineer 3.4.3

Released 2026-09-11 with partial qualification, at the maintainer's
direction. External ownership, independent review, corrections, and Codex
acceptance were demonstrated on real implementation work. Automated release
checks and GitHub CI passed; publication does not establish measured savings.

The comparison has zero valid matched results. Its first attempt was
retained as invalid because inherited host instructions exposed later
implementation context; normal non-interactive consent also did not complete.
Clean-environment agent onboarding, refreshed native-host provider acceptance,
and Desktop wait/recovery checks remain incomplete. These requirements remain
in the release process and are follow-up qualification work, not passed gates.
See the public evidence on PR43
for failures, limitations, and the separately reported setup accounting.

Installation ·
Configuration · Troubleshooting ·
Release process

Installation erratum

For 3.4.3, invoke setup directly from the release checkout:

node plugins/codex-co-engineer/bin/setup.mjs
node plugins/codex-co-engineer/bin/setup.mjs --check

Use these in place of the npm --prefix … run setup and setup:check commands below. npm's inherited local prefix can otherwise place dependency files inside the plugin source, which Codex may copy into its cache. The published source itself is unchanged. The direct invocation passed setup and preserved the exact 476-file plugin inventory. Issue #44 tracks the code fix. The local installation check caught this; it is additional evidence that clean-environment onboarding is still unqualified.

Highlights

Before With 3.4.3
Corrections and checks often return to the lead agent Bounded external ownership keeps implementation, checks, and up to three correction rounds with the producer
Completion can be mistaken for acceptance or savings Ordinary results expose compact evidence; unknown usage stays unknown; no invented savings claim
Extended deadlines did not always govern the active turn Supported deadline extensions govern the active ACP turn and keep timeout/cancellation truthful
New contributors lacked a first outcome and evaluation path Onboarding example, support routes, contributor tasks, frozen cases, and an offline analyzer

Ownership and corrections

Delegate complete engineering assignments—preparation, implementation,
meaningful checks, and requested corrections—to the external owner. Codex and
other lead agents retain independent review and final acceptance.

  • Role preferences and an explicit provider choice preserve ownership for that
    request; they do not infer balances or silently replace an active worker.
  • task.revision returns bounded findings to the same owner and scope within
    the existing five-tool catalog (status, delegate, task, tasks,
    cancel).
  • Correction chains cap at three rounds. Duplicate or conflicting feedback is
    explicit; identical repeated requests stay safe without prompt replay.
  • One admitted child per producer is reserved across server processes, with
    lineage retained through restart.

Truthful evidence

Ordinary run replies include compact result_evidence tied to the existing
usage ledger and decision-card helpers.

  • Show measured submissions, available elapsed time, candidate identity, and
    review state when known.
  • Unknown usage stays unknown. Completion is never Codex acceptance.
  • Do not convert native tokens into subscription dollars or invent percentage
    savings from fixtures.
  • PR43 retains the real
    development evidence and unsuccessful evaluation attempt. Actual matched
    measurements remain pending under the published budget rules; development
    cases and synthetic fixtures do not establish workload reduction.

Deadline fix

Supported deadline extensions govern the active ACP turn, including concurrent
sessions and late provider output. Timeout and cancellation remain truthful
after partial provider output. Direct terminal uncertainty to inspection and
keep active work on bounded waits.

ACP results now settle after persistent-client finalization, so an immediate
runtime close can clean up the retained agent and its descendants. Cursor
corrected a real CI cleanup failure through two owned revisions; Grok checked
the final commit independently, including stress checks and a regression that
fails against the prior runtime. Astra accepted the correction.

Onboarding and contributor package

  • One-provider first-outcome example under examples/first-outcome in the
    v3.4.3 source. Clean-agent completion remains unverified.
  • Issue forms, PR template, SUPPORT.md, contributor tasks, and a roadmap that
    separates this adoption package from later work.
  • Frozen comparison cases and an offline analyzer that count native helpers,
    corrections, and failed attempts. Synthetic fixtures do not establish savings.
  • OpenAI showcase preparation notes the current local-MCP submission limitation
    without submitting a listing.

Upgrading

Install the published tag

Finish or cancel active runs before upgrading. Preserve a dirty development
clone and install from a separate clean clone:

git clone --branch v3.4.3 --single-branch https://github.com/ajhcs/Codex-Co-Engineer.git Codex-Co-Engineer-3.4.3
cd Codex-Co-Engineer-3.4.3
npm --prefix plugins/codex-co-engineer run setup
codex plugin marketplace add "$PWD"
codex plugin add codex-co-engineer@codex-co-engineer
npm --prefix plugins/codex-co-engineer run setup:check

Keep this clone as the registered marketplace source. For an existing public
installation, remove codex-co-engineer@codex-co-engineer with codex plugin remove before adding it again from this new source. Start a new Codex session
and ask for Co-Engineer status. Historical compatibility and the previous
release remain documented in the 3.4.2 notes.

The public release keeps the marketplace identity codex-co-engineer in the
shipped manifest. Prefer a clean Codex environment for onboarding. If older
open projects share that identity, create a distinct local marketplace wrapper
outside the tracked release, with the unchanged plugin name and exact released
plugin bytes. Remove/re-add alone is not sufficient: opening an older project
can replace the same-name cache again. Do not rename the shipped manifest to
solve a local collision.

From an already-installed local 3.4.3 candidate

Finish or cancel active runs. If older open projects still share the public
marketplace identity, refresh through a distinct local marketplace wrapper
outside the tracked candidate (unchanged plugin name and exact tested bytes),
then restart the Codex session. Remove/re-add alone may not survive opening an
older same-identity project. Do not assume the version string proves that the
currently running MCP process contains the new build. Existing durable state
retains its prior directory identity for compatibility. Do not delete task
state or provider login files as an upgrade step.

Muse OpenRouter migration

Users still on a direct Meta Muse profile must migrate to OpenRouter as
documented for 3.4.2. That
migration is unchanged in 3.4.3.

Compatibility

The public MCP catalog remains exactly five tools. No new MCP tools, quota
router, or automatic balance routing ship in 3.4.3. Published 3.4.2
behavior remains the baseline for arms that intentionally install that release.
Cursor compatibility package versioning is independent and is not bumped here.

Requirements and known limits

  • Node.js 24+, Git, Python 3.11+ for bundled setup, and Codex plugin support are
    required. The release gate runs on Node.js 24 for reproducibility.
  • Local providers require Linux, a working systemd --user manager,
    systemd-run 244+, unified cgroup v2, and Python 3.11+ for the bundled
    worktree tool. Lifecycle control is not a sandbox.
  • Publication is not a substitute for host acceptance, clean-environment
    agent onboarding evidence, or the budgeted comparison cohort.
  • Missing evaluation evidence is inconclusive; it is not a pass.

Validation

Keep every existing exact-candidate gate, CI, host, and native-run acceptance
requirement in the release process. Additional 3.4.3 evaluation
rules there cover the $25 TOTAL API/Cloud cap, seed43 cohort shape, accounting,
acceptance thresholds (including Astra own-output versus published 3.4.2; helpers
do not satisfy), and clean-environment onboarding. Do not treat provider-free
fixture suites or this document as live provider proof.

Final candidate evidence

Reviewed commit: c0aada7b76a1b4a42b5de20878293268d915321b
Released tree: e8bf87014d372355329bf4a6386887a5fb542a54
Main merge commit: 2907aa41baa9bfbcc4c7342b83d929a4ae8544aa (verified to contain the same tested tree)

The final publication checks also exposed a close/finalization race that could retain a live agent and reopen its stored record after close. Astra froze a deterministic regression; Grok implemented the minimal correction; Cursor independently verified the exact commit and the failing parent control; Astra accepted it. The rejected broad fix is not included. Both provider tasks completed with normal cleanup. The review's dropped connection was reconciled from durable completion without replaying its prompt.

The final exact-candidate gate passed 17 stages and 2,495 tests, with one reproducible build in 174.265 seconds (run 20260911T195734Z-f5c8b5e49e34). Candidate CI, final branch CI and final PR CI provide the hosted checks. The publication record retains the failures, controls and correction history.

This is a published release with partial qualification at the maintainer's direction. Measured benefit, authenticated clean-agent onboarding, refreshed native-host provider acceptance and Desktop wait/recovery remain unverified. The comparison is inconclusive, not a successful savings result. Paid API/Cloud use remains $0 against the approved $25 aggregate ceiling; an enforceable route bound is required before further paid dispatch.